The Coding-Agent Trap: When a „Free“ LLM Endpoint Is the Adversary, (Mon, Aug 31st)

ORIGINAL QUELLE:
isc.sans.edu

Quelle: SANSISC

One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide „free“ LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.

← Zurück zum security Archiv (31.08.2026)